AEPD (Spain) - EXP202406239
| AEPD - EXP202406239 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 24 GDPR Article 32 GDPR Article 32(1)(b) GDPR Article 58(2)(d) GDPR Article 83(2) GDPR Article 83(4)(a) GDPR Article 118 LPACAP Article 123 LPACAP Article 28(1) LRJSP Article 48(1) LOPDGDD Article 63(2) LOPDGDD Article 76(2) LOPDGDD |
| Type: | Other |
| Outcome: | n/a |
| Started: | |
| Decided: | |
| Published: | 29.04.2026 |
| Fine: | 1,000,000 EUR |
| Parties: | Iberdrola Clientes, S.A.U. |
| National Case Number/Name: | EXP202406239 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | Nata |
The DPA rejected an energy company's internal appeal and upheld a €1,000,000 fine under Article 32 GDPR, holding that a call centre identity verification protocol based on static, easily accessible customer data was inadequate.
English Summary
Facts
Iberdrola Clientes, S.A.U., an electricity retailer of the Iberdrola group (the controller), verified the identity of customers calling its call centres under an internal guide dated 19 March 2023. Under this protocol, a caller passed the identity check (PSI) by providing 4 out of 9 possible categories of data, such as surname, national ID number (DNI), contract reference, address, telephone number, e-mail address, bank account or supply point code (CUPS).
According to the controller, on 20 January 2023 the data subject called to request a copy of an invoice and provided an e-mail address, which the controller then linked to the contract as a permanent contact address. The e-mail address belonged to the data subject's daughter. No recording of the call was kept, nor any record of the data requested to verify the caller's identity. On 22 November 2023, the distributor of the group sent an e-mail concerning a request to modify the technical conditions of the data subject's contract to that address. On 17 January 2024, the distributor informed the data subject that the controller had provided the address. The data subject denied ever having given it as a contact address and filed a complaint with the DPA.
The DPA initially declared the complaint inadmissible, but admitted it after the data subject successfully appealed that decision internally. On 17 January 2025, the DPA opened sanctioning procedure PS/00459/2024 against the controller for a violation of Article 32 GDPR. On 14 January 2026, the DPA imposed a fine of €1,000,000 under Article 83(4)(a) GDPR and, under Article 58(2)(d) GDPR, ordered the controller to demonstrate within three months the adoption of security measures adequate to the risk, including protocols guaranteeing identity verification.
On 16 February 2026, the controller filed an internal appeal (recurso de reposición, file EXP202406239). It argued that (i) the DPA had ignored its submissions to the proposed resolution, causing a violation of its right to be heard and the nullity of the decision; (ii) the DPA had violated the presumption of innocence by imposing the fine without sufficient evidence or reasoning; (iii) the DPA had applied impermissible strict liability, since no intent or negligence had been established; (iv) the fine was disproportionate, in particular compared with a €500,000 fine imposed on a bank in file EXP202500113 for an incident the controller considered more serious; (v) the DPA had not considered mitigating factors; and (vi) the corrective measures had lost effect because, in the controller's view, the final resolution had not included them.
Holding
The DPA rejected all grounds of appeal and confirmed the fine of €1,000,000 and the corrective order.
First, on the alleged violation of the right to be heard, the DPA held that no submissions to the proposed resolution had ever been received, neither around the date claimed by the controller (14 November 2025) nor under the registry number it cited, and that the controller had not even attached the alleged proof of filing to its appeal. Since the controller had been able to make submissions at every stage of the procedure, no violation of its right of defence had occurred. The DPA also recalled, under Article 118 GDPR Article 118 LPACAP, that facts and documents which a party could have submitted during the hearing phase but did not cannot be taken into account when deciding an appeal.
Second, on the presumption of innocence, the DPA held that the sanctioning resolution had established, on the basis of the documents in the file, that the verification protocol did not meet the requirements of Article 32 GDPR. The guide listed nine categories of data but did not specify which four an agent had to request in each case or according to which criteria. The data used were static and, in many cases, easily accessible to third parties, and allowing verification with any 4 of 9 categories widened the combinations an unauthorised third party could know or deduce. The DPA held that this did not amount to multi-factor verification, since the system combined only personal data of the holder without any additional authentication factor such as passwords or one-time codes. It also held that the guide itself allowed agents to update a customer's telephone number or e-mail address when these appeared spontaneously during a conversation, without asking for the customer's confirmation, which could compromise future authentication and the accuracy of the database. Finally, the lack of any record of which data were requested and provided during verification made it impossible to reconstruct the process in case of an incident or audit, contrary to Article 32(1)(b) GDPR and the accountability duty in Article 24 GDPR.
Third, on strict liability, the DPA held that the infringement had been committed at least negligently. Citing the CJEU judgment of 5 December 2023, C‑807/21 (Deutsche Wohnen), and Spanish case law, it noted that a controller can be fined under Article 83 GDPR when it could not have been unaware of the infringing nature of its conduct. Although Article 32 GDPR imposes an obligation of means rather than of result, an entity of the controller's size could not be considered to have adopted measures adequate to the risk when its verification, traceability and database update procedures showed clear deficiencies.
Fourth, on proportionality, the DPA held that the fine was calculated under the GDPR's own system, which applies as lex specialis over the general rules of administrative law. Starting from a turnover of €11,353,755,000, the maximum fine under Article 83(4) GDPR was €227,075,100. To set the level of seriousness under Article 83(2) GDPR and the EDPB Guidelines 04/2022 on the calculation of administrative fines, the DPA considered that all of the controller's customers were potentially affected (contextualised with the figure of 7,146,778 supply points), that the infringement lasted more than 18 months, and that the data at stake, including DNI and bank account numbers, qualified as sensitive within the meaning of the Guidelines even though they were not special categories under Article 9 GDPR. Negligence was assessed as neutral. As aggravating factors, the DPA applied Article 83(2)(e) GDPR, given a previous infringement in PS/00398/2021, and Article 76(2)(b) LOPDGDD in relation to Article 83(2)(k) GDPR. It rejected the comparison with the €500,000 fine in EXP202500113, since that bank had a turnover more than ten times lower, an infringement lasting less than six months and no prior sanctions.
Fifth, the DPA rejected the mitigating factors invoked, holding that circumstances which the law defines as aggravating cannot be applied as mitigating, and that cooperation with the supervisory authority is an obligation under the GDPR rather than a mitigating factor.
Sixth, the DPA dismissed the claim that the corrective measures had lost effect, pointing out that both the legal reasoning and the operative part of the sanctioning resolution expressly ordered the controller to demonstrate, within three months, the adoption of technical and organisational security measures adequate to the risk, including identity verification protocols.
Comment
The decision confirms the AEPD's position that knowledge-based identity verification relying on static customer data does not satisfy Article 32 GDPR for a large energy retailer, and that the absence of any log of the verification steps is itself a security failure because it prevents the controller from demonstrating compliance. The DPA's reading of "sensitive data" for fine calculation purposes is also worth noting: following the EDPB Guidelines 04/2022, it treats national ID and bank account numbers as sensitive even though they fall outside Articles 9 and 10 GDPR. The reasoning on the missing submissions is striking, as the entire nullity ground rested on a filing of which the DPA found no trace and which the controller did not document in its appeal either. The decision exhausts the administrative procedure; the controller may still challenge it before the Spanish National Court (Audiencia Nacional).
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/27 • File No.: EXP202406239 RESOLUTION OF THE APPEAL FOR RECONSIDERATION Having examined the appeal for reconsideration filed by IBERDROLA CLIENTES, S.A.U. (hereinafter, IBERCLI) against the resolution issued by the Presidency of the Spanish Data Protection Agency dated January 14, 2026, and based on the following FACTS FIRST: On January 14, 2026, a resolution was issued by the Presidency of the Spanish Data Protection Agency in file EXP202406239, by virtue of which it was decided: - TO IMPOSE on IBERDROLA CLIENTES, S.A.U., with Tax Identification Number A95758389, for an infringement of Article 32 of the GDPR, classified in Article 83.4.a) of the GDPR, a fine of €1,000,000.00 (ONE MILLION EUROS). - ORDER IBERDROLA CLIENTES, S.A.U., with Tax Identification Number A95758389, to, pursuant to Article 58.2.d) of the GDPR, within a maximum period of 3 months from the date this resolution becomes final and enforceable, demonstrate compliance with the corrective measure established in legal basis VII: Demonstrate the adoption of appropriate technical and organizational security measures, considering the risk of the personal data processing carried out, including the implementation of protocols that guarantee the verification of the identity of the data subjects. This resolution, which was notified to the appellant on January 15, 2026, was issued following the processing of the corresponding disciplinary proceedings, in accordance with the provisions of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and, supplementarily, Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), regarding the processing of disciplinary proceedings. SECOND: As proven facts in the aforementioned sanctioning procedure, PS/00459/2024, the following were recorded: “FIRST: On September 16, 2024, IBERCLI, a marketing company of the Iberdrola Group, provided the Agency with a guide dated March 19, 2023, which is used by all its call centers to verify the identity of its customers when they wish to carry out any transaction. SECOND: The aforementioned document is titled “***DOCUMENT.1” and, in its content, details the identity verification procedure and the database update procedure used by IBERCLI, as follows: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/27 (…) THIRD: On November 22, 2023, at 12:08 PM, I-DE Redes Electricas Inteligentes (***EMAIL.1), (…), sent an email to the claimant at the email address ***EMAIL.2 belonging to his daughter, informing him of his request to modify the technical conditions of the contract he held. FOURTH: On January 17, 2024, the Iberdrola Group's distribution company informed the claimant that the email address ***EMAIL.2 had been provided by IBERCLI, the group's energy retailer. The claimant states that he did not provide the email address ***EMAIL.2 to IBERCLI as a contact address. FIFTH: IBERCLI asserts, in a letter dated September 16, 2024, to this Agency, that on January 20, 2023, the claimant provided the email address ***EMAIL.2 to request a supply invoice and that, “as a result of the call, the email address ***EMAIL.2 became linked to the claimant's contract.” It also asserts that the claimant's identity was verified during the call on January 20, 2023, using protocol “***DOCUMENT.1” of March 19, 2023, as detailed in Finding Two. SIXTH: There is no recording of the call on January 20, 2023, nor the data that was required to verify the claimant's identity.” THIRD: On February 16, 2026, IBERCLI filed an optional appeal for reconsideration with this Agency, based, in summary, on the following: 1. Material lack of due process due to the infringement of the constitutional right of all interested parties to be heard (Article 105.c) of the Spanish Constitution) due to the actions of this Agency, which alleges that no record exists of the submission of arguments to the Proposed Resolution, despite the fact that their effective submission has been duly documented. REFERENCE 1. 2. Violation of the principle of presumption of innocence due to the insufficient assessment of the evidence and the lack of justification for the resolution, which is contrary to the principles governing the administrative sanctioning procedure. It is emphasized that IBERCLI acted with due diligence, implementing appropriate technical and organizational measures to guarantee the security of personal data and the correct identification of clients. 3. Inadmissibility of strict liability 4. Lack of proportionality in determining the amount of the imposed sanction and mitigating circumstances not considered. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/27 LEGAL BASIS I Jurisdiction The Presidency of the Spanish Data Protection Agency has jurisdiction to resolve this appeal, in accordance with the provisions of Article 123 of the LPACAP and Article 48.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD). II Response to the Allegations Presented Regarding the statements made by IBERCLI, we proceed to respond to them in the order presented: PREVIOUS.- BACKGROUND In this section, IBERCLI provides a chronological summary of the actions that have taken place in case file EXP202406239 from the time the claim was received by this Agency until the appealed decision was issued. It emphasizes that this Agency did not notify IBERCLI of the decision on the appeal for reconsideration filed by the claimant against the dismissal of their claim, causing them serious harm because they held the status of an interested party, as recognized by the Supreme Court (Administrative Law Chamber, Section 4) in its Judgment No. 1181/2023, of September 25 (Appeal No. 8072/2020). Furthermore, it concisely sets forth what will later constitute the arguments on which the appeal for reconsideration filed against the resolution issued by this Agency within the framework of sanctioning procedure PS/00459/2024 is based. In this regard, this Agency reiterates what has already been stated throughout sanctioning procedure PS/00459/2024 regarding the failure to notify IBERCLI of the resolution upholding the appeal for reconsideration filed by the claimant against the dismissal of their claim. Specifically, that “the aforementioned resolution upholding the appeal for reconsideration filed by the claimant concludes that there is sufficient evidence to justify admitting the claim for processing due to the possible existence of a data protection infringement, as provided for in Article 65 of the LOPDGDD. In this regard, it is important to distinguish between the actions aimed at determining the admissibility of a claim, in accordance with Article 65 of the LOPDGDD (including the transfer actions provided for in Article 65.4) and the initiation of a sanctioning procedure by means of a formal initiation agreement as required by Article 68 of the LOPDGDD and in accordance with the provisions of Article 64 of the same law. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/27 Transfer actions are those that the regulations allow this Agency to take, without being mandatory, before the claim is admitted for processing. In this case, transfer actions were carried out on April 26, 2024, which initially determined that the claim was inadmissible. The decision to dismiss the claim was notified to the claimant in compliance with Article 65.5 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), which stipulates that the decision regarding the admissibility or inadmissibility of the claim must be notified exclusively to the claimant, who is the only party entitled to file an appeal for reconsideration in accordance with Article 123 of the LPACAP (Law on the Common Administrative Procedure of Public Administrations). Subsequently, the claimant filed an appeal for reconsideration, which was upheld, resulting in the claim being admitted for processing. This decision regarding the appeal for reconsideration filed The decision issued by the claimant followed the submission of allegations granted to IBERCLI, and only addresses the admissibility of the claim. It was not served on IBERCLI, given the aforementioned Article 65.5, which only requires notification to the claimant. Furthermore, it cannot be asserted, under any circumstances, that IBERCLI was “an interested party in the proceedings,” since no proceedings had been initiated.The initiation of these disciplinary proceedings was carried out by means of an initial agreement dated January 17, 2025, which was duly notified to IBERCLI on January 21, 2025. This agreement alleged a violation of Article 32 of the GDPR, as defined in Article 83.4 of the GDPR, set an initial penalty of €1,000,000, and granted IBERCLI a period for submitting arguments. All of this is without prejudice to any determinations made during the investigation. In short, within the framework of these proceedings, IBERCLI has been able to request any evidence it deemed appropriate and submit arguments, and therefore, no violation of its right to a fair hearing can be found. Regarding the remaining issues raised by IBERCLI, these will be addressed in the following sections. Therefore, this allegation is dismissed. FIRST.- ON NULLITY. IBERCLI alleges a situation of material defenselessness as provided for in Article 47.2 of the LPACAP (Law on Administrative Procedure of Public Administrations), due to the infringement of the constitutional right enshrined in Article 105 c) of the Spanish Constitution of every interested party to be heard. It states that on November 14, 2025, it submitted allegations to the proposed resolution of the sanctioning procedure PS/00459/2024, but that in the appealed resolution, this body omitted these allegations, causing it real and effective defenselessness. In this regard, it indicates that it is attaching as Document No. 1 to this optional appeal for reconsideration a copy of the receipt of Submission with registration number ***REFERENCE.1. IBERCLI indicates that in its arguments against the proposed resolution, it provided evidence demonstrating that the identity verification process complied with the security and traceability requirements. Specifically, it detailed the data that was required from the claimant to verify their identity, as well as the security measures implemented, which demonstrated that IBERCLI had and has an identification method in accordance with Article 32 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5/27 IBERCLI also alleges a continuous violation of the guiding principles of the administrative procedure throughout the process, culminating in a situation of defenselessness that materializes in the effective privacy of the hearing process and, consequently, a violation of Article 24 of the Constitution Spanish. Therefore, IBERCLI understands that this is not a mere formal defect or flaw, but rather a substantive infringement that has caused an actual violation of the rights recognized in the Spanish Constitution (Articles 24 and 105) and that, according to the Supreme Court ruling rec. 7983/1999 of July 11, 1999, the absence of a hearing process renders the act null and void. That is, in this case, Article 47.1 a) of the LPACAP (Law on the Common Administrative Procedure of Public Administrations) is fully applicable. In this regard, this Agency wishes to point out that, after carrying out the necessary checks, there is no record of IBERCLI submitting any written arguments against the proposed resolution of sanctioning procedure PS/00459/2024 around the indicated date—November 14, 2025—nor with the registration number ***REFERENCE.1. no other. It is also emphasized that, even though the appellant bases its appeal for reconsideration on this fact and maintains that it attaches a document proving the submission of said allegations, it does not attach any documentation to accompany its appeal. Given the above, the correct procedure of this Agency in issuing the resolution of the sanctioning procedure PS/00459/2024 is beyond doubt, and IBERCLI cannot claim lack of due process. Thus, as already stated in the resolution under appeal and reproduced in the response to the previous allegation, it is emphasized that the present sanctioning procedure was initiated by agreement dated January 17, 2025, and notified on January 21, 2025. IBERCLI was given a period for submitting allegations, which were received on February 11, 2025, after having been granted This Agency requested an extension of the deadline pursuant to Article 32 of the LPACAP. Contrary to what IBERCLI now seems to imply, it did not request the holding of a hearing for the taking of evidence pursuant to Article 77 of the LPACAP. Nor were any other allegations or documentation submitted beyond the written statement of objections to the initiation agreement of February 11, 2025, that should have been taken into account for the purpose of issuing the proposed resolution pursuant to Article 53.1 e) of the LPACAP. In light of the foregoing, the procedural officer issued a proposed resolution, duly reasoned in accordance with the requirements of Articles 89.3 and 35 of the LPACAP, establishing a period of 10 days for IBERCLI to submit any allegations and documentation it deemed appropriate. All of this was done in accordance with Article 89.2 of the LPACAP and with the character prior to the Spanish Data Protection Agency (AEPD) issuing a resolution. There is a record of notification of the aforementioned proposed resolution to IBERCLI dated October 23, 2025. Subsequently, on October 24, 2025, IBERCLI requested an extension of the 10-day period granted for submitting arguments against the proposed resolution. This extension was granted and agreed upon on October 30, 2025. It is also recorded that IBERCLI was notified of this extension on the same day. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/27 On January 14, 2026, the period for submitting arguments against the proposed resolution having long since expired, and without any written submission having been received (and without any record of it to this day; the appellant having failed to provide proof of either its content or its submission), the The Presidency of the Spanish Data Protection Agency (AEPD) issued the resolution now under appeal. Consequently, it can only be stated that the resolution concluding the disciplinary proceedings is lawful and that IBERCLI was in no way deprived of its right to be heard and to submit documentation and any arguments it deemed appropriate at the various stages of the proceedings. Therefore, this appeal is dismissed. SECOND.- ON THE VIOLATION OF THE PRESUMPTION OF INNOCENCE AND EFFECTIVE JUDICIAL PROTECTION AS A CONSEQUENCE OF THE INADEQUATE ASSESSMENT OF THE EVIDENCE AND THE LACK OF JUSTIFICATION IN THE RESOLUTION. IBERCLI argues that the imposed sanction “was issued without any evidentiary element that would allow for proof of the alleged breach, nor, in any case, the existence of a causal relationship between an isolated event and the alleged infringement stemming from the supposed failure to adopt adequate security measures and that “the contested resolution suffers from a serious lack of reasoning, resulting from the absence of a genuine and effective examination of the allegations and the documentation provided by IBERCLI.” In this regard, it cites, with respect to the importance of the reasoning behind judgments—and that by extension this would apply to any authority exercising public sanctioning powers—Supreme Court Judgment 303/2015, of June 25, and Supreme Court Judgment 421/2015, of July 22. IBERCLI maintains that it has demonstrated with the evidence submitted in its arguments against the proposed resolution of sanctioning procedure PS/00459/2024 that “(i) no modification to the client's data can be carried out without its prior verification and acceptance, an essential requirement according to the internal procedures current; and that (ii) in cases where a change of email address is requested, the process requires a double layer of security, so the new email address must be verified by the user before being activated in the system.” Regarding the identity verification procedure, IBERCLI argues that the provided Guide does establish clear, uniform, and fully verifiable criteria, which are precisely defined in “***DOCUMENT.1” and in the Identity Verification Procedure (IVP), where the data to be requested is identified in a structured manner according to the type of operation, the contact channel, and the associated risk level. Therefore, it has been fully demonstrated that the Guide expressly identifies the valid data for passing the identity verification procedure (IVP)—surname, national identity document number, contract reference, full address, telephone number, email address, bank account number, CUPS number, claim number, or SIC number in the email channel—and also sets minimum thresholds. Verification based on the channel C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/27 used, precisely defining the identification standard required in each case.” It also argues that the data it requests is aligned with the requirements established by the National Commission on Markets and Competition (hereinafter, CNMC) in its “Information Guide for Electricity Consumers,” as well as with the Resolution of the Procedure for the adoption of a Legally Binding Decision of the CNMC regarding the significant increase in supplier changes without consent due to errors in the selection of the CUPS code; a document that “expressly highlights the need to thoroughly verify data—especially the CUPS code-address combination and the identity of the account holder—in order to prevent improper changes and unauthorized access.” Therefore, it believes that this Agency is mistaken when It states that it lacks a multi-factor verification system because its system is “based on the simultaneous, coherent, and structured combination of various personal data, and not on the isolated use of a single identifier.” Regarding database updates, IBERCLI argues that it is not true that an agent could update them without the prior and necessary consent of the interested party, a requirement expressly stated in the Guide; and that, if during the conversation the client has already provided their phone number and/or email address, this data can be used to update the database “if applicable” without eliminating the verification process. Thus, IBERCLI asserts that “under no circumstances is it authorized to dispense with the identity verification process; on the contrary, a dynamic verification model is contemplated, based on the information confirmed by the client during the interaction, (...). However, the Spanish Data Protection Agency (AEPD) fails to assess this obligation —expressly stated in the Guide just one paragraph earlier—to obtain the client's confirmation before proceeding with any update of their personal data.” Regarding the nature of the data being processed, IBERCLI alleges a contradiction in the Agency's reasoning when it maintains that certain data are easily accessible or deducible by a third party and, at the same time, classifies that same set of information as especially sensitive. This contradiction "demonstrates a deficient assessment of the actual risk and an abstract evaluation that fails to consider the specific characteristics of the data processed and its context of use," and therefore, IBERCLI believes that it "cannot serve as grounds for intensifying the sanction or for disqualifying, without sufficient justification, the security measures implemented by IBERCLI, designed precisely to address the relevance and operational sensitivity of the information processed." Finally, IBERCLI insists that it submitted to the Agency, along with the proposed resolution, the certifications, including those in compliance with ISO 27001:2022 and EUROPRIVACY. which demonstrate the entity's compliance with advanced standards in information security and personal data protection. In this regard, and as a preliminary matter, this Agency reiterates what it has already stated regarding the written objections to the proposed resolution and the attached documentation. There is no record of their submission to this body, neither on the date supposedly indicated by IBERCLI in November 2025 nor now, along with the filing of the appeal for reconsideration. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/27 C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/27 alleged date of November 2025, nor now, along with the filing of the appeal for reconsideration. Furthermore, it is noted that these objections were already raised in response to the initial agreement and were duly addressed at that time. Therefore, reference should be made to Legal Basis III of the appealed resolution and, in particular, to the response to the second objection. Notwithstanding the foregoing, it should be noted that the sanctioning resolution subject to this appeal has explained and duly demonstrated, based on the documentation in the administrative file, that the customer identity verification procedure implemented by IBERCLI for use by its call center agents did not comply with the requirements of Article 32 of the GDPR. This is all as set out in the established facts and legal grounds of the aforementioned sanctioning resolution. At no point has this Agency indicated that the Guide “***DOCUMENT.1” does not clearly specify the data that the call center agent may request from the customer to verify their identity. Rather, of the nine possible data points that may be requested, the document does not specify which of these nine data points the agent should request depending on the customer's request. In this regard, this agency stated the following in the aforementioned sanctioning resolution: “It is also specifically stated that “the valid data for passing the PSI” are: “(…). Although another section of the document specifies that “(…)”, it does not specify the criteria for determining which data will be required in each case, nor the reason why one call requested the bank account number and another the telephone number. Similarly, this Agency maintains its position as stated in the sanctioning resolution regarding the “Information Guide for Electricity Consumers,” and in the Resolution of the Procedure for the Adoption of a Legally Binding Decision of the CNMC, which indicates that: “The data indicated in the aforementioned CNMC document on page 21, to which IBERCLI refers, corresponds to the documentation required for the purpose of entering into a contract, that is, the CUPS code, the contracted power, the supply address, the data of the supply contract holder, billing information, installation certificate, or electrical certificate. This data is required, as stated, for the purpose of formalizing a contract, while the present sanctioning procedure concerns IBERCLI's system for verifying the identity of its clients in order to carry out a specific transaction. Furthermore, it is emphasized that, contrary to what is indicated by IBERCLI, the data in question are not what appears in its protocol for the purpose of verifying identity, which is the subject of this procedure, (...). Therefore, the above does not correspond to IBERCLI having implemented a multi-factor authentication system, since this system requires the concurrence of several authentication factors and not only the verification of certain personal data. In short, the system implemented by IBERCLI does not combine the account holder's personal data with other authentication factors such as the use of passwords or the sending of temporary codes by message to the person claiming to be the contract holder. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/27 passwords or the sending of temporary codes by message to the person claiming to be the contract holder. Furthermore, regarding IBERCLI's assertion that the updating of customer data in its databases will only be carried out with the prior confirmation of the data subject, it should be noted that, contrary to what the appellant has stated, the Guide “***DOCUMENT.1” itself explicitly authorizes the agent to update the customer's telephone number and/or email address without needing to obtain such confirmation, since the agent can change this personal data when it arises during the conversation with the customer. That is, if the customer spontaneously mentions such personal data, the agent has the authority to decide whether to use it and modify it in their database, but, under no circumstances does it stipulate that they must ask the customer if they wish to have this personal data entered into the system in order to modify the existing data. And, in this regard, this Agency already expressed its position in the sanctioning resolution when it indicated that: “it is worth referring to the database update procedure (DBDD) included in the protocol provided by the respondent, which states that, during interactions with the client, contact information in the database can be updated without explicit confirmation from the interested party. Thus, it states: “If the client contacted us more than a month ago, we assume that their information may have changed in that time. Confirm this information with them, and if it is missing or has changed, update it. When conducting the PSI (Personal Identification System) check, they may have already provided you with their phone number and/or email address, or this information may have come up in the conversation without you having to ask. Take advantage of this to update the database if you deem it necessary.” This practice presents several deficiencies that would also imply non-compliance with the aforementioned Article 32, among others, for the following reasons: - It is not guaranteed that the client is aware that data provided for a specific procedure will be permanently recorded in the database. - Thus, for example, if an email address were updated in this way and that updated email address were used as a verification criterion, the client might not be aware of it, potentially compromising future authentication. - Updating databases without a clear validation process can lead to the storage of incorrect or unverified data, affecting the accuracy and reliability of the information. Finally, this Agency wishes to point out that easily accessible data is not synonymous with it being especially sensitive, as the determining factor is different. That is, in the first case, it refers to how that data is obtained (either through a family or professional relationship, for example), while data that is especially sensitive from the perspective of Guidelines 04/2022 on the calculation of fines refers to the consequences of its disclosure or the immediate difficulties that its disclosure to a third party would cause the data subject. Thus, in the aforementioned guidelines, the EDPB recognizes as sensitive data not only the special category data of Article 9 of the GDPR, but also the data of Article 10 of the same regulation and others such as the National Identity Document (DNI), in consideration of the consequences that the loss of control over this data could have for the data subject. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/27 Therefore, this claim is dismissed. THIRD.- ON THE INADMISSIBILITY OF STRICT LIABILITY: THE ABSENCE OF INTENT, FAULT, OR GROSS NEGLIGENCE AND OF RESIDUAL RISK. IBERCLI argues that the existence of the subjective element of the infringement (intent, fault, or negligence) that would allow for the imposition of an administrative sanction based on the GDPR has not been proven, in accordance with the requirements of Article 83 of the GDPR, Article 28.1 of the Law on the Legal Regime of the Public Sector, and the repeated case law of the Supreme Court and the Court of Justice of the European Union. IBERCLI indicates that culpability is not presumed and that it must be proven that the responsible party failed to fulfill the duty of care required at the time of the events, a matter that is not reflected in the sanctioning resolution. This does not identify any intentional act or specific negligent omission attributable to IBERCLI and merely expresses a technical disagreement regarding the design of the security measures adopted; which, by itself, is legally insufficient to support a judgment of guilt and, consequently, to justify a sanction. It cites Judgment 164/2005 of the Constitutional Court of June 20, 2005, which establishes that “sanctions cannot be imposed based solely on the result and through apodictic reasoning; specific justification regarding culpability or negligence and the evidence from which it is inferred is essential.” IBERCLI understands that, for its part, “it has not limited itself to generically denying guilt, but has provided detailed, documented, and verifiable evidence that it exercised due diligence through the implementation of reasonable technical and organizational measures, a formalized identity verification procedure based on multifactor criteria, active confirmation mechanisms, and controlled data update procedures.” IBERCLI argues that the lack of due diligence attributed to it by this Agency cannot be justified on the grounds that the measures implemented by the entity did not, in its opinion, reach the desired level. Personal data protection regulations do not require the absolute elimination of any risk, but rather the adoption of appropriate and reasonable measures, taking into account the nature, context, and purposes of the processing; a requirement that IBERCLI affirms it more than adequately met. Therefore, “the occurrence of an isolated incident, despite the existence of such measures, cannot automatically become a judgment of guilt.” IBERCLI concludes that the above is contrary to Supreme Court Judgment 188/2022, of February 15, which establishes that the obligation to adopt security measures is an obligation of means, not requiring the infallibility of the implemented measures. In this regard, this Agency reiterates what was already stated in the sanctioning resolution regarding the lack of due diligence required on the part of IBERCLI: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/27 “It should be noted that the principle of liability established in Article 28.1 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector, provides that: “Only natural and legal persons, as well as, when a law recognizes their legal capacity, groups of affected parties, associations and entities without legal personality, and independent or autonomous estates, who are responsible for such acts due to intent or negligence, may be sanctioned for acts constituting an administrative offense.” To that effect, the Judgment of the Court of Justice of the European Union of December 5, 2023, in case C-807/21 (Deutsche Wohnen), states: “76. In this respect, it should also be clarified, with regard to the question of whether an infringement has been committed intentionally or negligently and, therefore, may be sanctioned with an administrative fine under Article 83 of the GDPR, that a controller may be sanctioned for conduct falling within the scope of the GDPR when it could not have been unaware that its conduct was infringing, whether or not it was conscious of infringing the provisions of the GDPR (see, by analogy, the judgments of 18 June 2013, Schenker & Co. and Others, C-681/11, EU:C:2013:404, paragraph 37 and the case law cited therein; of 25 March 2021, Lundbeck v Commission, C-591/16 P, EU:C:2021:243, paragraph 156, and of 25 March 2021, Arrow Group and Arrow Generics/Commission, C 601/16 P, EU:C:2021:244, paragraph 97). Along these same lines, the courts of our country express their views. Thus, the Supreme Court (Administrative Law Chamber, Section 5) in Judgment No. 179/2023, of February 15, 2023, establishes: Judgment (STS 354/2023) (...) we must begin by recalling that culpability is indeed a requirement for administrative offenses, inherent in Article 25 of the Constitution, which has undergone extensive doctrinal development within the field of Criminal Law, from which Administrative Sanctioning Law derives. This requirement entails, in brief for the purposes of the debate at hand, that the act defined in the offense can and must be attributable to the sanctioned individual, who is considered guilty, that is, responsible, according to the terminology of the Law. of the Common Administrative Procedure of Public Administrations. This imputation entails an intellectual element according to which the typical action is not only carried out by the subject himself, but is done consciously and willingly, that is, intentionally, or through more or less intense negligence, insofar as the diligence required in the execution of the act to avoid the harmful effect has been omitted. In turn, the Judgment of the National Court, of January 21, 2010, states: “The appellant also maintains that there is no culpability whatsoever in her actions. It is true that the principle of culpability prevents the admission of strict liability in administrative sanctioning law; it is also true that the absence of intent is secondary, since this type of infraction is normally committed through culpable or negligent conduct, which is sufficient to constitute the subjective element of fault.” XXX's actions are clearly negligent because… he should be aware of… the obligations imposed by the LOPD on all those who handle personal data of third parties. XXX is obligated to guarantee C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/27 the fundamental right to the protection of personal data of its clients and potential clients with the intensity required by the content of the right itself.” Likewise, it should be noted that the Supreme Court (Judgments of April 16 and 22, 1991) considers that the element of culpability implies “...that the action or omission, classified as an administratively sanctionable offense, must, in all cases, be attributable to its author, due to intent or recklessness, negligence, or inexcusable ignorance.” The same Court reasons that “it is not enough... for exoneration from typically unlawful conduct to invoke the absence of fault” but rather that it is necessary “that the diligence required by the one alleging its non-existence has been employed.” (Supreme Court Judgment of January 23, 1998). Furthermore, it is worth noting that the method of attributing liability to legal entities does not correspond to the forms of intentional or negligent culpability that are attributable to human conduct. Therefore, in the case of offenses committed by legal entities, although the element of culpability must be present, it is necessarily applied differently than it is applied to natural persons. According to Constitutional Court Judgment 246/1991, "(...) this distinct construction of the imputability of the authorship of the offense to the legal entity arises from the very nature of the legal fiction to which these subjects are subject. They lack the volitional element in the strict sense, but not the capacity to infringe the rules to which they are subject." Capacity to infringe and, therefore, direct culpability derived from the legally protected interest of the rule that is infringed and the need for said protection to be truly effective and from the risk that, consequently, the legal entity subject to compliance with said rule must assume" (in this sense, STS of November 24, 2011, Rec 258/2009). To the above, it must be added, following the judgment of January 23, 1998, partially transcribed in the STS of October 9, 2009, Rec 5285/2005, and of October 23, 2010, Rec 1067/2006, that "although the culpability of the conduct must also be proven, it must be considered, in order to assume the corresponding burden, that ordinarily the volitional and cognitive elements necessary to assess it form part of the conduct typical proven, and that its exclusion requires proof of the absence of such elements, or, in its normative aspect, that the diligence required by the party alleging its non-existence has been employed; in short, the mere invocation of the absence of fault is insufficient for exoneration from conduct that is typically unlawful." In the present case, the imputed acts occurred, at least, in a negligent manner, insofar as IBERCLI's identity verification protocol has shortcomings that prevent it from complying with the obligations imposed by the GDPR, particularly those relating to guaranteeing data security. The adoption and implementation of security measures appropriate to the risk. It cannot be overlooked that the risk-based approach and the flexible risk model imposed by the GDPR are based on a dual configuration of security as a principle relating to processing and an obligation for the controller or processor. In this regard, the judgment of the National High Court of Justice of October 17, 2007 (appeal no. 63/2006) is very illustrative, stating that “…the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. And in assessing the degree of diligence, special consideration must be given to the professional status of the individual, and there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data, the emphasis must be on the rigor and meticulous care required to comply with the applicable legal provisions.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/27 To deny the existence of negligence on the part of IBERCLI would be tantamount to acknowledging that its conduct—whether by action or omission—has been diligent. Obviously, this perspective of the facts is not shared, and this Agency reiterates that document “***DOCUMENT.1” demonstrates that the identity verification and database update procedure is deficient in guaranteeing an adequate level of security against the risks.” On the other hand, this Agency wishes to point out that, while the obligation to implement security measures under Article 32 of the GDPR is an obligation of means and not of results, it is nonetheless true that IBERCLI did not adopt appropriate technical and organizational measures to guarantee a level of security appropriate to the risk, taking into account the "state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as risks of varying likelihood and severity for the rights and freedoms of natural persons." It cannot be assumed that an entity of IBERCLI's size had security measures appropriate to the possible risks when the identity verification, traceability, and database update procedures present clear deficiencies, which were already detailed by this Agency in the sanctioning resolution, especially in section IV, Legal Basis: "Article 32 of the GDPR requires data controllers to adopt appropriate security measures." Technical and organizational security measures appropriate to the risk that guarantee that the processing complies with current regulations. It is necessary to point out that the aforementioned provision does not establish a list of specific security measures according to the data being processed, but rather establishes the obligation for the data controller and processor to implement technical and organizational measures that are appropriate to the risk involved in the processing, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks of likelihood and severity for the rights and freedoms of data subjects. Likewise, security measures must be appropriate and proportionate to the risk identified, determining the appropriate technical and organizational measures, taking into account pseudonymization and encryption, the ability to guarantee confidentiality, integrity, availability, and resilience, the ability to restore data availability and access after an incident, a verification process (not audit), and an evaluation and assessment of the effectiveness of the measures. In any case, when assessing the adequacy of the security level, particular consideration must be given to the risks presented by data processing, as a consequence of the accidental or unlawful destruction, loss, or alteration of personal data C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/27 transmitted, stored, or otherwise processed, or the unauthorized disclosure of or access to such data, which could cause physical, material, or immaterial damage. Furthermore, Recital (74) of the GDPR states that: “The controller must be held responsible for any processing of personal data carried out by the controller or on behalf of the controller. In particular, the controller must be obliged to implement appropriate and effective measures and must be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. Such measures should take into account the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons.” Therefore, this principle, applied to the processing of personal data held by the controller, necessary to carry out a specific activity, requires that such processing be carried out using technical and organizational methods that guarantee the security and confidentiality of such personal data. In this case, IBERCLI indicated in its letter of September 16, 2024, regarding security measures, that (i) “attached as Annex I is the guide followed by our Call Center on PSI control, whose function is to guarantee the security of the client's personal data and contract” and that (ii) “when requesting services by telephone, it will be necessary for the person to identify at least four pieces of information, which may be the following: (...)”. The protocol contained in the annex is dated March 19, 2023. From the content of the aforementioned Annex 1, the content of which is detailed in the Proven Facts of this document, it is clear that it is possible to identify oneself as the holder of a contract, request a copy of the invoice, and modify the contract details, including the email address to which the invoice should be sent, by knowing four of nine categories of data. That is, it is possible to comply with the requirements using only easily accessible personal data that cannot be modified by the data subject and is not unique to the contract, which is insufficient to prove the data subject's identity. Similarly, in this case, there is no clear record of the checks carried out during the identity verification process. This directly affects traceability, since: - It is not possible to determine what data was requested and provided by the person who requested access to the billing information and/or a modification (for example, a change of email address). - There is no evidence to verify whether the data provided was correct or whether an error was made. As indicated above, Article 32.1 b) requires technical and organizational measures that guarantee the confidentiality and integrity of personal data. In this regard, the choice of four data categories as a criterion for verifying C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/27 the client's identity cannot be considered sufficient to fulfill the objective pursued by the aforementioned article, for the following reasons, among others: - The data used for verification ((…)) is static information and, in many cases, easily accessible. - Allowing the identification of the data subject with 4 out of 9 possible data categories significantly increases the risk of identity theft and unauthorized access, as it expands the combinations of information that an unauthorized third party can know or deduce. Furthermore, the email channel only requires confirmation of two additional pieces of information, besides the email address, which further reduces the level of security, unlike what would occur, for example, in the case of a multi-factor authentication system. For its part, the lack of traceability in the identity verification and personal data modification procedure also implies non-compliance with Article 32 of the GDPR. The absence of a clear record documenting what data was provided by the applicant, how it was verified, and what specific actions were taken makes it impossible to reconstruct the process in the event of an incident or audit. Without an adequate record, it is not possible to determine whether the data provided was correct, whether the verification was effective, or whether the actions taken were authorized by the legitimate data subject. This leaves the controller without the tools to demonstrate that appropriate security measures have been applied to the level of risk, as required by the GDPR. Not surprisingly, and related to the above, it is worth noting that Article 24 of the GDPR, when addressing the controller's responsibility, states that “taking into account of the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that processing is in accordance with this Regulation. These measures shall be reviewed and updated where necessary” (Emphasis added by the Spanish Data Protection Agency). Consequently, the lack of a secure and traceable identity verification procedure not only compromises the security of personal data, but also limits the controller's ability to guarantee the effective protection of data subjects' rights, which contravenes the provisions of Article 32 of the GDPR. On the other hand, it is worth mentioning the database update procedure outlined in the protocol provided by the respondent, which states that, during interactions with the client, contact information can be updated in the database without explicit confirmation from the data subject. Specifically, it states: “(…)” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/27 This practice presents several deficiencies that would also constitute a breach of Article 32, among others, for the following reasons: - There is no guarantee that the client is aware that data provided for a specific transaction will be permanently recorded in the database. - Thus, for example, if an email address were updated in this way and that updated email address were used as a verification criterion, the client might not be aware of it, potentially compromising future authentication. - Updating databases without a clear validation process can lead to the storage of incorrect or unverified data, affecting the accuracy and reliability of the information. Finally, the procedure described in the Annex allows the use of any of the following data categories to pass the PSI verification: (...). However, the protocol does not specify the criteria under which the four data categories required for verification are selected, which implies a flexibility that allows the control data to be adapted according to what the data subject may know. In this sense, the absence of a standardized protocol to determine which data should be requested in each case significantly reduces the system's ability to guarantee the confidentiality and integrity of personal data, as required by Article 32 of the GDPR. This lack of clear criteria for selecting control data demonstrates a lack of proportionality in the security measures implemented and would generate a structural risk affecting all clients. By way of illustration only, it should be emphasized that the complainant's case is an example of the deficiencies in the analyzed protocol and, consequently, of the shortcomings in the security measures in question. Thus, even though IBERCLI asserts—contrary to the complainant's claims—that the complainant's daughter's email address was provided by the complainant on January 20, 2023, when requesting a copy of a utility bill, and that the complainant subsequently underwent the identity verification process outlined in the aforementioned protocol, there is no recording of the call, nor any proof that the complainant bypassed the identity verification process, nor any record of the data requested during the call, nor of what data was provided. Furthermore, it is striking that, even though IBERCLI itself states in its letter of September 16, 2024, that the email address was provided to request a duplicate invoice, it was linked as permanent contact information. Beyond this specific example, everything discussed ultimately demonstrates that IBERCLI has not been sufficiently diligent in implementing security measures appropriate to the risk to the rights and freedoms of the data subjects affected by its processing, specifically regarding the verification of their identity, as stated in its protocol of March 19, 2023. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/27 Consequently, at no point is the legal basis for the infringement of Article 32 of the GDPR attributed to IBERCLI by this Agency limited to an obligation of result, much less to an isolated incident. At all times, it is stated that the deficiencies in the identity verification, traceability, and database updating procedures pose a generic risk to all clients subject to them. Therefore, this allegation is dismissed. FOURTH.- ON THE LACK OF PROPORTIONALITY IN SETTING THE AMOUNT OF THE PROPOSED SANCTION. IBERCLI continues by alleging that it believes this Agency has also violated the guiding principles of the administrative sanctioning regime and the criteria established in Guidelines 04/2022 on the calculation of administrative fines under the GDPR of the European Data Protection Board (EDPB), and that, consequently, the infringement is disproportionate. Thus, IBERCLI argues that the imposition of a sanction in an administrative sanctioning procedure must comply with the provisions of Article 29 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector (hereinafter, LRJSP) in order to respect the principles of suitability and necessity in the choice of the sanctioning measure; and that, however, this Agency merely cites Article 83 of the GDPR to justify the sanction for the infringement of Article 32 of the GDPR. In this regard, Article 83 of the GDPR provides that the administrative fines imposed by the supervisory authorities shall, in each individual case, be effective, proportionate and dissuasive; without the sanctioning resolution justifying the necessity and proportionality of the imposed sanction. In relation to the above statements, the following clarifications are necessary: - The lack of proportionality of the sanction was already alleged against the initial agreement, and this allegation was duly answered at the time, as stated in the appealed resolution, to which reference is made, without prejudice to the fact that it is deemed appropriate to highlight some aspects below. - Regarding the alleged lack of motivation in the resolution, it should be emphasized that the motivation for the imposed sanction is found in Legal Basis VI, which, after setting out the provisions of Articles 83.1 and 83.2 of the GDPR, as well as Article 76 of the LOPDGDD, determines the elements that must serve as a starting point for determining the level of severity of the infringement in accordance with the provisions of Guidelines 04/2022 and determines the differences in the assessment Regarding the circumstances surrounding the investigation of the proceedings, the circumstances of Articles 83.2 a), b), and g) are analyzed, and subsequently, the applicable aggravating factors are determined for the case. The content of the resolution is reiterated when, in response to the allegations against the initial agreement, it states: “Furthermore, it is necessary to emphasize that, as indicated in Guidelines 04/2022 on the calculation of fines under the GDPR, there are three elements as C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/27 starting points for imposing a fine: the turnover, the categorization of the infringements according to their nature (i.e., whether they are infringements of 83.4, 83.5, or 83.6 of the GDPR), and the level of severity of the infringement in each specific case. This level of severity should not be confused with the term “seriousness” traditionally used in Spanish case law for the purpose of classifying an infringement as very serious, serious, or minor. The level of severity referred to in the GDPR must be determined by considering the circumstances of Article 83.2(a): the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation, the number of data subjects affected, and the level of damage caused; Article 83.2(b): the intentionality or negligence of the infringement (which should not be confused with the requirement of objective and subjective culpability under Spanish law); and Article 83.2(g): the categories of personal data affected. Based on this starting point determined by these three elements, aggravating or mitigating circumstances may be applied (the remaining elements of Article 83.2 of the GDPR in relation to Article 76.2 of the LOPDGDD). - Regarding these elements, the initial agreement established an initial penalty of €1,000,000, which was substantially increased during the investigation of the proceedings, as justified in Legal Basis III of the resolution. Finally, the resolution agrees to set the amount initially foreseen in the initial agreement, understanding that, notwithstanding the appropriate assessment made by the investigating officer in the proposed resolution, it was necessary to take into account (i) the decrease in IBERCLI's business volume, (ii) that, for the purposes of Article 83.2(e) of the GDPR, only one infringement was established, unlike in the initial agreement, and (iii) that the maximum number of potential data subjects was considerably lower than that assessed during the investigation. This is stated in Legal Basis VI of the appealed resolution. - Regarding the claims concerning the need to apply Article 29 of the LRJSP, it should be noted that Article 63.2 of the LOPDGDD stipulates the following: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them, subsidiarily, by the general rules on administrative procedures.” The GDPR establishes its own system of sanctions and determination of the amount of the fine in Article 83, without prejudice to the fact that it provides for the subsidiary application of the basic principles of sanctioning law. Therefore, in accordance with the principle of normative specialty (lex specialis derogat legi generali), the special law (that is, the provisions of the GDPR and the LOPDGDD) takes precedence over the general law, which shall apply subsidiarily. Thus, the criteria for determining the severity of the penalty are those expressly provided for in the GDPR. - Therefore, in light of the above, the resolution, when setting the penalty, as expressly stated therein, is based on a turnover of €11,353,755,000. Regarding the categorization of the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/27 infringement, this is classified under Article 83.4 of the GDPR, which stipulates that the penalty imposed may reach a maximum of the higher of €10,000,000 or 2% of the infringing entity's annual turnover. Therefore, in the case under sanction proceedings, the fine would necessarily have to be between €0 and €227,075,100. Next, it analyzes the circumstances of Article 83.2 a), b), and g) for the purpose of determining the level of severity. The following aspects can be highlighted, without prejudice to the fact that reference is made to this section of the resolution: Regarding Article 83.2 a) of the GDPR: The resolution focuses on the impact on all IBERCLI clients, precisely because it is a procedural infringement. Special emphasis is placed on the fact that when the security measures of Article 32 are compromised, the control of data subjects over their data is affected. Furthermore, the duration of the infringement is taken into account, which exceeds 18 months. Regarding Article 83. b) of the GDPR: it was not considered when determining the amount of the penalty, precisely because it was considered that there was no greater level of negligence than the minimum required for the principle of culpability or liability to be present. In these cases, Guidelines 04/2022 refer to a "neutral" assessment for the purpose of determining the amount of the fine. Regarding Article 83.2 g) of the GDPR: the affectation of sensitive data is taken into account, as provided for in Guidelines 04/2022. Furthermore, the provisions of Article 83.2 e) of the GDPR and a previous infringement in PS/000398/2021 are considered as aggravating factors, as well as the provisions of Article 76.2 b) of the LOPDGDD (in relation to Article 83.2 k) of the GDPR). In light of all the above circumstances, the fine is set at €1,000,000. Considering the percentage that this amount represents in relation to IBERCLI's turnover, it cannot be deemed disproportionate. Furthermore, IBERCLI cites file no. EXP202500113 from this Agency, which, according to IBERCLI, would support the claim of disproportionality based on the fact that the resolution imposed a fine of €500,000 on ING for infringement of Article 32 of the GDPR, “even though the scope of the incident was much greater: the deficiencies identified were structural, affected access control mechanisms, and compromised financial and banking data, such as customer identification information, contact details, and data relating to financial products and services. The level of sensitivity and the risk associated with such data is, objectively, much higher than that present in this case.” In this regard, it should be noted that the jurisprudential doctrine of the Supreme Court and the Constitutional Court, in relation to equality in the application of the law, maintains that it has a formal character and that it aims to prevent arbitrary pronouncements, so that the law is interpreted equally for everyone. Furthermore, case law has clearly defined C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/27 its characteristics and scope, indicating that it encompasses and gives content to a prohibition or discrimination such that equal situations must be treated equally, and therefore, this principle of equality can only be invoked as violated when, given the prior requirements of equality of situations between the objects affected by the rule, there is differential treatment of them by virtue of arbitrary and unjustified conduct by public authorities, thus "the profiles within which the action brought in defense of this fundamental right to equality must be developed are framed with rigorous precision, which must be understood as being between equals, that is, between those who have all the same circumstances..." (Supreme Court Judgment of June 23, 1989), since “Not every disparity in treatment constitutes discrimination; rather, the disparity in solutions must arise in absolutely identical situations” (Supreme Court Judgment of October 15, 1986). Consequently, “this principle must require… an absolute identity of factual circumstances…” (Supreme Court Judgment of March 28, 1989). In addition to the absolute identity of these factual premises, which is lacking in the cases presented, the application of the principle of "equality in the application of the law" requires proof that such action was arbitrary and discriminatory (Supreme Court Judgment of July 13, 1989), since Article 14 of the Spanish Constitution excludes the possibility that "the final decision issued appears to be the result of mere selective voluntarism compared to previous cases resolved differently" (Constitutional Court Judgments 55/1988, of March 24; 181/1987, of November 13; and 1/1990, of January 15). This requirement is also not present in the case at hand. Taking this into account, it is emphasized that the circumstances in case file EXP202500113 differ from those in the present case. Thus, by way of example, the following is highlighted: (i) ING's turnover taken into consideration in the resolution is more than ten times lower than IBERCLI's, (ii) the duration of the infringement did not exceed 6 months, compared to at least almost 18 months in the case of IBERCLI, and (iii) ING had not been previously sanctioned for data protection violations, unlike IBERCLI. Furthermore, IBERCLI raises the following issues regarding the "aggravating factors" invoked by this Agency in the sanctioning resolution: - Nature and seriousness of the infringement (Article 83.2(a) of the GDPR): IBERCLI reiterates that it has not been proven that the infringement was widespread, nor that it lacked security measures appropriate to the risk. It insists on the absence of any incriminating evidence on this matter. In this regard, it is necessary to clarify, once again, that the appealed resolution cites Article 32 of the GDPR regarding the lack of security measures appropriate to the risk in relation to a protocol used to verify the identity of its clients, and refers to Legal Basis III and IV of the resolution, which extensively substantiate the existence of the infringement. - Number of affected data subjects: IBERCLI points out that the consideration of a total of 7,146,778 supplies is incorrect, as it does not differentiate between natural and legal persons and because it considers that in no case do all of its clients use the call center. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/27 In this regard, two aspects should be clarified: First, as indicated in Guidelines 04/2022, when referring to affected parties, both actual affected parties and potential affected parties must be counted. In this case, all of IBERCLI's clients are considered potential affected parties with respect to data protection, since any of them may use the call center. Furthermore, regarding IBERCLI's claims that the figure of 7,146,778 is not adequate, it is striking that IBERCLI neither determines nor provides proof of the correct number of clients.In any case, it is emphasized that the resolution indicates that all of IBERDROLA's customers are potentially affected under the circumstances of Article 83.2 a) of the GDPR. These effects are referenced to contextualize the potential number of affected parties to the maximum figure of 7,146,778 people, as this is the number of supplies contained in Annex 3 of the report by the CNMC (National Commission for Markets and Competition) entitled "Retail Gas and Electricity Report 2024" (IS/DE/027/25 - IS RETAIL GAS AND ELECTRICITY MARKET. 2024 | CNMC). In this regard, it is emphasized that the proposed resolution contained a maximum figure of more than 11 million customers (that is, higher than the figure contained in the resolution). This difference was one of the factors taken into account to reduce the amount of the penalty in the appealed resolution compared to that contained in the proposed resolution. It is therefore emphasized that the proposed resolution referred to a maximum number of potentially affected parties higher than the figure finally contained in the resolution, without any allegations being recorded. to said amount, since no objections to the proposed resolution have been filed. In this regard, reference should be made to the provisions of Article 118 of the LPACAP, which states: “Facts, documents, or objections of the appellant shall not be taken into account in the resolution of appeals when, having been able to submit them during the objection process, they have failed to do so.” IBERCLI insists that no damages have occurred, and therefore it should refer to the content of the resolution: “Furthermore, in relation to the assertion that no “damage to third parties” has occurred, it is worth noting that the right to data protection is a fundamental right constitutionally recognized in Article 18.4 of the Spanish Constitution. This fundamental right recognizes the right of citizens to control their data, whether or not this data has a constitutional dimension. The alleged lack of measures affects the sphere of the fundamental right to data protection of all IBERCLI clients.” or Regarding the duration of the infringement, IBERCLI believes that the Spanish Data Protection Agency (AEPD) cannot consider the date of a document that is merely indicative for C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 22/27 the agents as the starting date of the infringement. However, it omits the fact that it was IBERCLI that submitted the document “***DOCUMENT.1” along with its response letter of September 16, 2024, indicating that “Attached as Annex I is the guide followed by our CALL CENTER on PSI control (…)” and that included the date March 19, 2023, in the document itself. At no point during the sanctioning procedure has IBERCLI treated that date as merely indicative. Regarding Article 83.2 b) of the GDPR, IBERCLI maintains that The principle of culpability is not present in this case, since there is no negligence or intent on the part of IBERCLI. In this regard, it should be noted that, as has already been explained throughout this appeal resolution, the necessary conditions for the presence of the principle of culpability are present in this case, allowing for the processing of the corresponding disciplinary proceedings. However, with regard to the assessment of any special negligence or intent that must be taken into account for the purpose of determining the amount of the sanction, it is reiterated that this has not been done in the sanctioning resolution, following the guidelines established by Directive 04/2022, which indicate the neutral nature of this circumstance when no special negligence or intent is found. Regarding the circumstance of Article 76.2 b) of the LOPDGDD in relation to Article 83.2 k) of the GDPR, IBERCLI maintains that this circumstance is not directly related to the case and that the incident analyzed is due to an isolated human error. In this respect, it is worth reiterating that the appealed resolution alleges a violation of Article 32 of the GDPR due to the absence of security measures linked to a protocol of the appellant, which came to light as a result of a complaint. Therefore, it is not appropriate to speak, as has been extensively argued in the sanctioning resolution, of an isolated incident. Similarly, it is also undeniable that the infringer's activity is closely linked to the processing of personal data, given the very nature of the products offered and, furthermore, that the aforementioned protocol allows for the verification of customer identity for purposes such as modifying their personal data held by IBERCLI. Regarding the circumstances of Article 83.2 g) of the GDPR, IBERCLI argues that its assessment in the resolution is incorrect, since sensitive data is a special category of data, and this type of data was not involved in the present case. In this regard, it is necessary to reiterate what was expressly stated in the appealed resolution: “The categories of personal data affected by the infringement (Article 83.2(g) of the GDPR): Guidelines 04/2022 of the European Data Protection Board on calculating fines under the GDPR, adopted on May 24, 2023, in paragraph 57, state the following regarding the requirement to take into account the categories of personal data affected: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 23/27 “(…) the GDPR clearly highlights the types of data that deserve special protection and, therefore, a stricter response with regard to fines. This refers, at a minimum, to the types of data referred to in Articles 9 and 10 of the GDPR and to data outside the scope of these articles whose disclosure would cause immediate harm to the data subject (for example, location data, data on private communications, national identification numbers, or financial data, such as transaction summaries or credit card numbers). In the present case, the personal data processed that would be affected by the lack of measures range from the national identity card number to the bank account number. That is, the concept of sensitive data used in the resolution corresponds to the definition contained in Guidelines 04/2022. Finally, with regard to the circumstances of the present case, this Agency wishes to reiterate once again, as stated in the resolution under appeal, that, contrary to what IBERCLI indicated, not all the circumstances were considered "aggravating factors." For these purposes, the following are recalled: explanations already provided regarding the fact that the circumstances of Article 83.2, points a), b), and g) of the GDPR, in accordance with the provisions of Guidelines 04/2022, are circumstances for the purpose of determining the level of seriousness of the infringement. Once the level of seriousness has been determined, the mitigating and aggravating circumstances that correspond and that are contemplated in Article 83.2 c), e), f), h), i), j), and k) of the GDPR would be applied; the latter in relation to the provisions of Article 76.2 of the LOPDGDD. Therefore, these allegations are dismissed. FIFTH.- ON THE CONCURRENCE OF MITIGATING FACTORS NOT CONSIDERED. IBERCLI argues that “In the interest of procedural efficiency, this party reiterates all the arguments made throughout the sanctioning proceedings and emphasizes the full applicability of the mitigating circumstances repeatedly presented, which are clearly present in this case and must be assessed in accordance with Article 83.2 of the GDPR and EDPB Guidelines 04/2022.” In this regard, this Agency reiterates what was already stated in the Sanctioning Resolution in which the allegations regarding the initial agreement on this matter were addressed: “Regarding the claims that mitigating circumstances have not been applied, it is reiterated, as has been indicated, that the application of mitigating and aggravating circumstances is carried out, in accordance with Guidelines 04/2022 once the level of severity of the fine has been determined, and the circumstances of Article 83.2 c), e), f), h), i), j), and k) may be applied; the latter in relation to the provisions of Article 76.2 of the LOPDGDD.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 24/27 Regarding the claim that the circumstances described in Article 83.2 k), in conjunction with Article 76.2 c), of the GDPR should have been considered mitigating factors, it should be noted that, as indicated in the judgment of the National Court of May 5, 2021, appeal no. 1437/2020, circumstances that the regulation considers aggravating factors cannot be considered mitigating factors. Specifically, it states: “the lack of the necessary condition for its application with respect to Article 76.2.c) of the LOPDGDD, that is, obtaining benefits as a consequence of the infringement, does not allow its application as a mitigating factor.” The same applies to Article 83.2 f), bearing in mind that cooperation with the supervisory authority by the data controller is an obligation established by the GDPR. In this regard, the same judgment states: “With respect to the proposed application as a mitigating circumstance of circumstance f) of Article 83.2 of the GDPR, 'the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its possible adverse effects,' it suffices to refer to what was stated in the Legal Basis to reject the application of this mitigating circumstance.” Furthermore, regarding the assertion that no “harm to third parties” has occurred, it is worth noting that the right to data protection is a fundamental right constitutionally recognized in Article 18.4 of the Spanish Constitution. This fundamental right recognizes the right of citizens to control their data, whether or not such data has a constitutional dimension. The alleged lack of measures affects the fundamental right to data protection of all IBERCLI customers.” Therefore, this allegation is dismissed. SIXTH.- ON THE ADOPTION OF MEASURES. IBERCLI understands that the corrective measures proposed in the Proposed Resolution “have been rendered ineffective and are inapplicable, as they were not ultimately included or agreed upon in the Resolution.” This omission is especially relevant, insofar as it demonstrates that the Administration itself did not deem it necessary to impose any additional measures at the time of its decision, which can only be interpreted as an implicit acknowledgment that IBERCLI already had sufficient and appropriate technical and organizational measures in place to guarantee the proper processing of personal data.” In this regard, this Agency expresses its surprise at the statement made by IBERCLI regarding corrective measures, given that there is a specific section on their adoption in the Seventh Legal Basis of the sanctioning Resolution: “VII Corrective Measures Article 58.2 d) of the GDPR stipulates that each supervisory authority may “require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time frame…”. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 25/27 Thus, the responsible entity may be required to adapt its actions to the personal data protection regulations, to the extent expressed in the preceding Legal Grounds. This act establishes the infringement committed and the facts that have given rise to this breach of data protection regulations, from which the measures to be adopted are clearly inferred, without prejudice to the fact that the specific procedures, mechanisms, or instruments for implementing them are the responsibility of the sanctioned party, since it is the data controller who fully knows their organization and must decide, based on proactive responsibility and a risk-based approach, how to comply with the GDPR and the LOPDGDD. However, in this case, regardless of the foregoing, in accordance with the evidence available at this time for the resolution of the sanctioning procedure, IBERCLI is required to, within THREE MONTHS from the date of enforcement of the final resolution of this procedure, adopt the following measures: - Demonstrate the adoption of technical and organizational security measures appropriate to the risk of the personal data processing carried out, including the implementation of protocols that guarantee the verification of the identity of individuals. It is advised that failure to comply with the order to adopt measures imposed by this body in the resolution of this sanctioning procedure may be considered an administrative infringement in accordance with the provisions of the GDPR, classified as an infringement in Articles 83.5 and 83.6, and such conduct may lead to the initiation of further administrative sanctioning proceedings. Likewise, the operative part of the Sanctioning Resolution also expressly includes, as a second section, the following regarding corrective measures: “SECOND: ORDER IBERDROLA CLIENTES, S.A.U., with Tax Identification Number A95758389, to, pursuant to Article 58.2.d) of the GDPR, within a maximum period of 3 months from the date this resolution becomes final and enforceable, demonstrate compliance with the corrective measure established in legal basis VII: - Demonstrate the adoption of technical and organizational security measures appropriate to the risk of the personal data processing carried out, including the implementation of protocols that guarantee the verification of the identity of individuals.” For the reasons stated above, these allegations are dismissed. III Conclusion C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 26/27 Consequently, in this appeal for reconsideration, the appellant has not provided any facts or legal arguments that would allow for a reconsideration of the validity of the challenged decision. IV Obligation to issue an express decision In accordance with the provisions of Article 24 of the LPACAP (Law on Administrative Procedure of Public Administrations), the meaning of administrative silence in proceedings for challenging acts and provisions is a rejection. However, even though the legally established time limit for issuing a decision has expired, the Administration maintains the obligation to issue an express decision and to notify it in all proceedings, regardless of how they are initiated, including any administrative appeals that may have been filed, as provided in Article 21.1 of the aforementioned LPACAP. LPACAP. In cases of dismissal by administrative silence, the express resolution subsequent to the expiration of the deadline will be adopted by the Administration without being bound in any way by the meaning of the silence, as provided in Article 24.3 of the same law. Therefore, even if the appeal is not resolved within the deadline, it is appropriate to issue the express resolution that concludes it. Having considered the aforementioned provisions and other generally applicable regulations, the Presidency of the Spanish Data Protection Agency RESOLVES: FIRST: TO DISMISS the appeal for reconsideration filed by IBERDROLA CLIENTES, S.A.U. against the resolution of this Spanish Data Protection Agency issued on January 14, 2026, in file EXP202406239. SECOND: TO NOTIFY IBERDROLA CLIENTES, S.A.U. of this resolution. THIRD: To warn the sanctioned party that the The imposed penalty must be paid once this resolution has been notified, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, within the voluntary payment period established by Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in conjunction with Article 62 of Law 58/2003, of December 17, by depositing it into restricted account no. ES00 0000 0000 0000 0000 0000, held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will proceed during the enforcement period. If the notification date falls between the following days The deadline for voluntary payment is the 1st and 15th of each month, inclusive. If the payment date falls between the 16th and the last day of each month, inclusive, the deadline is the 5th of the second following month or the next business day. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 27/27 In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be published once it has been notified to the interested parties. This resolution, which concludes the administrative process pursuant to Article 48.6 of the LOPDGDD, and in accordance with Article 123 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, may be appealed. Public (LPACAP), interested parties may file an administrative appeal with the Administrative Chamber of the National Court, in accordance with the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law. Finally, it should be noted that, pursuant to Article 90.3 a) of LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally communicate this fact in writing to the Spanish Data Protection Agency, submitting it through from the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of the aforementioned LPACAP. You must also submit to the Agency the documentation that proves the effective filing of the administrative appeal. If the Agency does not receive notice of the filing of the administrative appeal within two months from the day following notification of this resolution, it will consider the precautionary suspension terminated. 180-071125 Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es




